2

I'm using chrome://net-internals/#hsts to do HSTS testing.

I tried to query a domain that has HST preloaded (facebook.com), and got the expected results:

Found: static_sts_domain: facebook.com

However, I tried the following steps with a domain that is not preloaded (live.com)

  1. Go to http://live.com (I then get redirected to https://live.com)

  2. Query live.com domain for HSTS (using chrome://net-internals/#hsts) Results: Not found

  3. Go to https://live.com (directly typing HTTPS to avoid being redirected)

  4. Query live.com domain for HSTS (using chrome://net-internals/#hsts) Results: Found: dynamic_sts_domain: live.com

I don't understand why my query at step 2 didn't find anything. I got redirected, but I ultimately visited https://live.com and received a response that contained an HSTS header Strict-Transport-Security:max-age=63072000;includeSubDomains.

Bob Ortiz
  • 6,665
  • 11
  • 50
  • 96
user152086
  • 21
  • 1

0 Answers0